Skip to main content

Exposing a sensitive environment variable in the configuration can lead to credentials leak

SeverityExploitabilityProvidersCategories
CRITICALHIGHAWSSECRET

Description

The value of a sensitive environment variable is defined in plaintext.

Impact

Potential data exposureVisible in logsUser interaction requiredPrivileges required
TrueFalseFalseTrue

The secret is exposed to anyone with access to the configuration and from the AWS Management Console.

Remediation guidelines

Secrets should be pulled from a secure secret storage by the service using them.

References

How can I help you ?